On 17 September OpenAI released Astra for Law, a version of its GPT-6 Astra model packaged with a legal research index, instructions for legal analysis and writing, 26 plugins into tools like Relativity, Clio, iManage and Thomson Reuters HighQ, and a "Trusted Access" program with zero data retention for eligible firms. It is being offered to selected law firms first, with API access to follow.
If you run a law firm, an accounting practice, a broking business, a clinic or any other document-heavy professional services business in Melbourne, and you have a quote on your desk for a custom AI tool that reads documents and summarises them, this announcement should change what you do with that quote.
The model vendor has moved up into the workflow
Until now the deal was reasonably clear. OpenAI, Anthropic and Google sold raw capability. Everyone else — product companies, agencies, studios like ours — built the thing that sat between that capability and an actual job of work. Interfaces, permissions, integrations, review steps.
Astra for Law is OpenAI stepping into that middle layer. It is not a new model with better benchmark numbers. It is a model plus a search index plus opinionated instructions plus connectors plus a governance program, sold at a profession. OpenAI's own post describes forward-deployed engineers working inside firms to build custom interfaces and integrations: an agreement analyser at Sullivan & Cromwell, a deal diligence system at Ropes & Gray, an IPO preparation tool at Cooley.
Law is the first vertical, not the only one. The shape is what matters. Anywhere a profession has a well-trodden, text-heavy workflow, expect the same move.
The numbers are the vendor's own, and the gaps are worth noting
OpenAI reports that on 200 questions from the private validation set of Vals AI's Legal Research Bench, Astra for Law passed the overall correctness check on 54.0% of questions against 38.7% for the same model using plain web search — a 40% relative improvement, by their measure. It also published a side-by-side where a competing model cited a holding that had been reversed on appeal.
Treat all of that as vendor-reported, because it is. Fifty-four per cent correctness on a research benchmark is a long way from something you would let near a client matter unsupervised. The discussion on Hacker News picked up the obvious omission: the announcement says nothing about hallucination rates. Several commenters also noted that Harvey and Legora, named in the post as API customers building on the platform, are the same companies OpenAI is now shipping alongside. Today's ecosystem partner is tomorrow's competitor, and you should not architect anything on the assumption that a given layer of the stack will still exist in two years.
The research index stops at the US border
This part matters specifically for Australian readers. The legal search index covers US case law, statutes, regulations, court rules and administrative decisions — more than 230 million URLs, including the CourtListener collection from the Free Law Project, which OpenAI says covers over 99.9% of published US precedential case law.
There is nothing in the announcement about Victorian or Commonwealth authority. So if you were hoping to hand an Australian matter to this and get grounded local citations, that is not what shipped.
But the generic capability underneath it — read a pile of documents, compare them, extract terms, draft, flag inconsistencies — is jurisdiction-agnostic and already good. That is the part that just got cheaper for everybody, including your competitors.
Stop paying to rebuild the generic bit
Here is our position, plainly.
If the specification for your AI project reads like "clients upload documents, the system extracts the key terms, produces a summary, and answers questions about it", do not commission a custom build of that. It is now a commodity feature in a well-trodden vertical, and the people who make the models are building it themselves, in their own product, with their own distribution. You will spend six figures catching up to a moving target and then watch the target move again.
That applies to the obvious cases: contract review, intake triage, meeting and file summarisation, first-draft correspondence, FAQ answering over a document set. Buy that. Trial two vertical products for a quarter and pick one.
What is actually worth paying to build
The same announcement makes the case for where money should go, if you read it carefully. Every custom example OpenAI highlights is built on something the firm owns and nobody else has: its negotiating playbooks, its precedents, its method for working through a data room. And 26 of the launch items are plugins into systems firms were already running.
That is the pattern. Generic capability is bought. Value sits in three places, and they are the three places worth a custom build:
- Your own data, made usable. Most businesses have their institutional knowledge scattered across shared drives, email, a practice management system and someone's head. Getting it structured, permissioned and queryable is unglamorous work that no vendor will do for you, and it is the input every AI feature depends on.
- Integration into the systems you already run. The AI is not the hard part. Getting a result to land correctly in your practice management system, your job file, your invoicing, your CRM — with the right matter attached and the right person notified — is the hard part, and it is specific to your business.
- Data custody and exit terms. OpenAI is offering zero data retention on the API and excluding ChatGPT Enterprise usage from human review by default for eligible firms. Good. Make whoever you buy from put the equivalent in writing, and make sure you can get your data out in a usable form when you leave.
Build so the AI layer is swappable. If the model provider or the vertical vendor can be changed in a week without touching your integrations, you have bought yourself optionality against exactly the kind of announcement that just happened.
When it gets something wrong, it is your problem
One of the sharper questions in the Hacker News thread was who gets sued when the output is wrong. The answer, for you, is you. Nothing in a vendor's terms transfers your professional obligations to them.
So the non-negotiable design requirement is traceability and a human checkpoint. Every output that leaves your business should be traceable to a source document a person can open, and should pass through someone who is accountable for it. If a product cannot show you its sources, it is not fit for professional work, no matter how the demo looks.
What to do before you sign anything
Go back to whatever AI proposal you are currently holding and sort the scope into two piles: the parts that any competent vertical product will do within twelve months, and the parts that are specific to your data, your systems and your process. Cut the first pile from the build and go shopping for it instead.
Then ask your developer or vendor four questions. Where does our data physically live, and is it used for training? Can we export everything in a usable format, and what does that cost? If we swap the model behind this next year, what breaks? And show me the point in this workflow where a human signs off.
If the answers are vague, that is the whole answer.


